Finding · F-IAQ2-VUL-01

Critical vulnerabilities past remediation SLA

ClosedVUL-01 · Vulnerabilities are scanned and remediated within SLASecurity OperationsQ2 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. 11 critical findings on internet-facing AWS workloads were open beyond the 15-day SLA at the end of May.
Applications: Amazon Web Services (ap-south-1), GitHub Enterprise Cloud.
Potential risk
Unauthorised or erroneous transactions could go undetected and expose Meridian to financial loss and regulatory action.
Root cause
Container base images were not rebuilt on a schedule.
Agreed action plan

Remediate: critical vulnerabilities past remediation sla.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Ananya Rao
Target date
31 Jul 2026
Priority
High
Status
Closed

Evidence for this control (2)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-022Amazon Web Services (ap-south-1) · configuration report (Q2)VUL-01Amazon Web Services (ap-south-1)17 Jun 2026Rejected
Q2-EV-023GitHub Enterprise Cloud · ticket sample (Q2)VUL-01GitHub Enterprise Cloud22 Jun 2026Rejected

Tests of this control (1)

Open list →
TestControlCycleTestedByResultConfidence
TST-Q2-VUL-01VUL-01 · Vulnerabilities are scanned and remediated within SLAQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh